When you check whether a piece of safety hardware is allowed in a given safety integrity level, you are testing its architectural constraints, and the 2010 edition of IEC 61508 gives you two separate ways to do that check. Route 1H works from the device's safe failure fraction and a required hardware fault tolerance. Route 2H throws out the safe failure fraction and instead leans on real field-feedback reliability data backed by statistical confidence, with a simpler minimum fault tolerance fixed by the target level. Knowing which route a certificate or datasheet used tells you a great deal about how much redundancy your safety instrumentation actually needs.
Route 1H vs Route 2H in one line: Route 1H and Route 2H are the two permitted methods in IEC 61508:2010 for satisfying the architectural constraints on safety hardware. Route 1H uses tables that combine safe failure fraction with a minimum hardware fault tolerance for each integrity level; Route 2H ignores safe failure fraction and instead requires field-feedback reliability data with defined confidence limits plus a minimum fault tolerance set only by the target level.
Architectural constraints are a deliberate cap on how much integrity you are allowed to claim from a hardware architecture, no matter how good your failure-rate math looks. The idea is that a single reliability calculation can be optimistic or wrong, so the standard adds a second, more conservative gate. Route 1H and Route 2H are simply the two ways IEC 61508:2010 lets you pass that gate, and a device only needs to satisfy one of them.
Route 1H is the table-based method most engineers grew up with. You take the element's safe failure fraction, which is the proportion of its failures that are either safe or dangerous-but-detected, and you look up the required hardware fault tolerance for your target integrity level. A higher safe failure fraction lets you get away with less redundancy; a low safe failure fraction forces you to duplicate or triplicate the element. Type A simple devices and Type B complex devices use different tables, with Type B held to a stricter standard because its failure behavior is harder to fully characterize.
Route 2H drops the safe failure fraction entirely. Instead it asks for reliability data drawn from field experience, testing, or both, and it insists that the dangerous failure rates be stated with a stated confidence level rather than as a point estimate. In exchange for that statistical rigor, the minimum hardware fault tolerance is fixed purely by the target integrity level and the demand mode, with no table lookup on failure fraction. It is a fundamentally different bargain: prove your numbers are trustworthy, and the fault-tolerance requirement becomes simpler and often less punishing.
Route 1H suits newly designed or newly certified elements where a manufacturer has done a detailed failure analysis but does not yet have years of field returns to draw on. Because it rewards a high safe failure fraction, it pushes designers toward strong internal diagnostics, since diagnostics convert dangerous-undetected failures into dangerous-detected ones and lift the fraction. For a device with weak diagnostics and a low safe failure fraction, Route 1H can demand a level of redundancy that is expensive or physically awkward to install in the field.
Route 2H tends to fit mature, widely deployed field devices, the transmitters and valves that have accumulated a large installed base and a long, well-documented operating history. For such devices, the field-feedback data needed to state failure rates with confidence already exists, so the extra evidentiary burden is manageable. The payoff is that a proven device may meet the architectural constraint with less hardware fault tolerance than Route 1H would have forced, which can mean a single well-characterized element where the table route would have insisted on two.
The choice of route therefore feeds directly into redundancy decisions. If you are specifying a safety instrumented function and the sensor or final element only qualifies through Route 1H with a modest safe failure fraction, you may be committed to a voting architecture such as one-out-of-two to reach the required fault tolerance. If the same function can be built from devices justified through Route 2H on strong field data, you may reach the same integrity target with a leaner, cheaper architecture. Reading which route a supplier used is thus not a paperwork detail but a design input.
Whichever route qualified a device, the assumptions behind it only hold if the device keeps behaving the way the analysis expected. Route 2H in particular rests on field-feedback failure rates, and those rates are only as good as the operating history behind them. A cloud SCADA platform that continuously logs demands, trips, faults, and diagnostic states across a fleet of identical devices is quietly building exactly the kind of dossier that a reliability engineer needs to defend or revisit a Route 2H claim.
Because Merobix reads field instrumentation into one browser-based system, it can surface the operating context that route decisions depend on: how often a valve actually stroked, how many diagnostic alarms a transmitter raised, and whether spurious trips are creeping upward across a site. When that history contradicts the failure rates a certificate assumed, the architectural-constraint check that once passed may no longer be sound, and the visibility to catch that early is worth more than any single calculation.
None of this replaces the formal analysis that a certification body performs; a SCADA layer does not re-issue certificates or recompute safe failure fraction on its own. What it does is keep the real world in view so that engineers can tell whether the route-based claim on paper still matches the hardware in the field, and can gather the evidence they need before the next verification cycle.
No. A device only needs to satisfy one of the two routes to meet the architectural constraints for a given integrity level. Manufacturers pick whichever route they can support with their evidence, and a certificate will normally state which one was used.
Route 2H replaces the safe failure fraction approach with statistically confident field-feedback reliability data. The reasoning is that if you can demonstrate the dangerous failure rate directly, with a stated confidence limit, you no longer need the safe failure fraction as an indirect proxy for how trustworthy the hardware is. The minimum fault tolerance is then fixed by the target level alone.
Route 2H usually fits legacy, widely deployed instruments better because the long operating history needed to state failure rates with confidence already exists for them. Newly certified devices without much field data more often rely on the table-based Route 1H, which rewards strong internal diagnostics and a high safe failure fraction.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.